outline-agent

Pass

Audited by Gen Agent Trust Hub on Sep 28, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests and processes multiple external documents (idea.md, experimental_log.md, template.tex, conference_guidelines.md) provided in the workspace. This presents a surface for indirect prompt injection where adversarial content within these documents could attempt to influence the agent's logic. However, the skill mitigates this by applying a specific 'Anti-Leakage Prompt' and validating all output against a strict JSON schema.
  • Ingestion points: workspace/inputs/idea.md, workspace/inputs/experimental_log.md, workspace/inputs/template.tex, workspace/inputs/conference_guidelines.md.
  • Boundary markers: The instructions mandate prepending an anti-leakage-prompt.md to the system message.
  • Capability inventory: File read/write operations within the workspace and execution of a local validation script.
  • Sanitization: The output is strictly constrained to a JSON schema and verified by scripts/validate_outline.py.
  • [COMMAND_EXECUTION]: The skill executes a local utility script, scripts/validate_outline.py, using the system Python interpreter to validate the generated outline. This is an intended part of the workflow and operates on the skill's own output.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 28, 2026, 01:43 AM
Security Audit — agent-trust-hub — outline-agent